data-room
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
run_shell_command, providing a broad interface for executing system commands. This is intended for preparing and auditing materials but represents a significant capability level. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and audit external due diligence materials (contracts, equity documents, financials). Processing these untrusted inputs in conjunction with tools like
run_shell_commandandwrite_filecreates a surface where adversarial instructions hidden in documents could attempt to influence the agent's behavior. - [DATA_EXPOSURE]: The skill is explicitly designed to handle highly sensitive data, including
founder-context.md, capitalization tables, equity agreements, and financial records. Although the instructions include PII redaction protocols, the inherent access to these files is a critical part of the skill's risk profile.
Audit Metadata